
Hackers Exploit Claude to Breach OpenAI in Under 72 Hours
A trio of independent researchers named Hacktron used Anthropic’s Claude AI (Opus 4.8 and then Opus 5) to break into OpenAI systems by exploiting a Discourse image-upload bug and an OpenAI SSO flaw. They accessed an internal OpenAI discussion forum containing employee authentication tokens, potentially enabling further access to ChatGPT, Codex, Outlook, Slack, GitHub, and more. They proved their presence with a pull request to OpenAI’s internal codebase. The operation took place within 72 hours of discovery, and the researchers were paid $6,500 through OpenAI’s bug bounty program, highlighting how even AI builders can be vulnerable to sophisticated, human-guided exploits.













